Scheduled Queries reference information ↗
The table below lists the common fields in the Scheduled Queries page in Cortex XSIAM.
Note
Certain fields are exposed and hidden by default. An asterisk (*) is beside every field that is exposed by default.
Scheduled Queries table
| Field | Description |
|---|---|
| BQL | Whether the query was created by the native search. Native search has been deprecated, this field allows you to view data for queries performed before deprecation. |
| ISSUED BY | User who ran or scheduled the query. |
| MITRE ATT&CK TACTIC | MITRE ATT&CK tactics tagged in the scheduled query. |
| MITRE ATT&CK TECHNIQUE | MITRE ATT&CK techniques tagged in the scheduled query. |
| NEXT EXECUTION |
|
| PUBLIC API | Whether the source executing the query was an XQL query API. |
| QUERY DESCRIPTION | Query parameters used to run the query. |
| QUERY ID | Unique identifier of the query. |
| QUERY NAME |
|
| QUERY SYNTAX | The exact syntax used to write the query. |
| SCHEDULE TIME | Frequency or time at which the query was scheduled to run. |
| XQL | Whether the query was created by XQL search. |
